2026 CVE Vulnerabilities

68,230 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32297CRITICAL9.3The Angeet ES3 KVM allows a remote, unauthenticated attacker to write arbitrary files, including configuration files or ...
CVE-2026-32296HIGH8.8Sipeed NanoKVM before 2.3.1 exposes a Wi-Fi configuration endpoint without proper security checks, allowing an unauthent...
CVE-2026-32295CRITICAL9.3JetKVM before 0.5.4 does not rate limit login requests, enabling brute-force attempts to guess credentials.
CVE-2026-32294HIGH7JetKVM prior to 0.5.4 does not verify the authenticity of downloaded firmware files. An attacker-in-the-middle or a comp...
CVE-2026-32293MEDIUM6.3The GL-iNet Comet (GL-RM1) KVM connects to a GL-iNet site during boot-up to provision client and CA certificates. The GL...
CVE-2026-32292CRITICAL9.3The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess crede...
CVE-2026-32291HIGH7The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requ...
CVE-2026-32290HIGH7The GL-iNet Comet (GL-RM1) KVM before version 1.8.2 does not sufficiently verify the authenticity of uploaded firmware f...
CVE-2026-25770HIGH7.2Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 ...
CVE-2026-25769CRITICAL9.1Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.1...
CVE-2026-25534CRITICAL9.1### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddri...
CVE-2026-21570HIGH8.8This High severity RCE (Remote Code Execution)  vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, ...
CVE-2026-4148HIGH8.8A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issu...
CVE-2026-4147MEDIUM4.3An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is...
CVE-2026-28506MEDIUM4.3Outline is a service that allows for collaborative documentation. Prior to 1.5.0, the events.list API endpoint, used for...
CVE-2026-24901HIGH8.8Outline is a service that allows for collaborative documentation. Prior to 1.4.0, an Insecure Direct Object Reference (I...
CVE-2026-23759HIGH8.6Perle IOLAN STS/SCS terminal server models with firmware versions prior to 6.0 allow authenticated OS command injection ...
CVE-2026-21886HIGH8.1OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6....
CVE-2026-4318HIGH8.8A vulnerability was determined in UTT HiPER 810G up to 1.7.7-171114. Affected is the function strcpy of the file /goform...
CVE-2026-3564CRITICAL9A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material ...
CVE-2026-4324MEDIUM5.4A flaw was found in the Katello plugin for Red Hat Satellite. This vulnerability, caused by improper sanitization of use...
CVE-2026-3888HIGH7.8Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private ...
CVE-2026-4271HIGH7.5A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs...
CVE-2026-30911HIGH8.1Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop...
CVE-2026-28779HIGH7.5Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now